Latest CVE Feed
-
7.5
HIGHCVE-2005-2312
management.php in Realnode Emilda 1.2.2 and earlier allows remote attackers to perform actions as other users by modifying the user_id parameter.... Read more
Affected Products : emilda- EPSS Score: %0.72
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2309
Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.... Read more
Affected Products : opera_browser- EPSS Score: %1.86
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2323
Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3... Read more
- EPSS Score: %0.75
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2297
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.... Read more
Affected Products : easerver- EPSS Score: %71.53
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2322
Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.... Read more
- EPSS Score: %0.73
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2305
DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.... Read more
Affected Products : remote_control_server- EPSS Score: %7.31
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2326
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.... Read more
Affected Products : clever_copy- EPSS Score: %0.34
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2307
netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."... Read more
- EPSS Score: %46.80
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-2310
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.... Read more
Affected Products : winamp- EPSS Score: %7.72
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2196
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.... Read more
Affected Products : airport_card- EPSS Score: %0.07
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1530
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.... Read more
- EPSS Score: %5.98
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2304
Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.... Read more
- EPSS Score: %11.95
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2319
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.... Read more
Affected Products : yawp- EPSS Score: %0.52
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2308
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fence... Read more
Affected Products : ie- EPSS Score: %45.84
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2317
Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.... Read more
Affected Products : shorewall- EPSS Score: %0.99
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2325
Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock.php, (6) showlast.php, (7) showlast5class1.php, (8) sho... Read more
Affected Products : clever_copy- EPSS Score: %0.36
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2320
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.... Read more
Affected Products : webcalendar- EPSS Score: %0.75
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2313
Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.... Read more
Affected Products : secureclient_ng- EPSS Score: %0.05
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2311
SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.... Read more
Affected Products : sms- EPSS Score: %0.08
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2300
Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.... Read more
Affected Products : skype- EPSS Score: %0.10
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025